Rollout order after #94 (attribution, PR #95): #103 → #106 → #104 → #105. Builds on the hook #106 lands, so it follows container attribution.
Goal
Let a policy set enforce/audit mode and the default action per workflow step, instead of once for the whole job.
Motivating case: run enforce across a job but audit for one noisy step (a vendored test suite, a flaky integration step) without downgrading the entire job — today --audit-mode is a single boolean fixed for the daemon's lifetime.
Why it's small
Phase 0 already ships the hard part. Mode and default action are single-byte values in eBPF array maps, written through idempotent setters (SetAuditMode, SetDefaultAction) that are already called at runtime when SaaS policy overrides the CLI flag. The work is making the lookup per-policy rather than global:
- Replace the single-entry
map_audit_mode / map_default_action lookups in check_audit_or_block() with a per-policy lookup keyed on the socket's step tag (map_policy_meta[policy_id] → {default_action, audit}).
- Resolve socket tag → policy id in the TC path (the tag is already embedded in events; this extends it to the verdict path for these two fields only).
- Policy schema: per-step
mode / default_action overrides on top of the job baseline.
Requirements
- Sockets with no tag (pre-attach, or attribution unavailable) must resolve to the job baseline, never to a looser step policy.
- If step attribution fails to start, behavior must be identical to today's job-wide mode — the existing warn-and-degrade path.
- Established sockets keep their birth tag, so a step's mode applies to the connections that step created, including ones that outlive it.
Done when
A workflow can declare a different mode for one step, the audit log/summary show that step's events under the declared mode, and every other step is unaffected.
Rollout order after #94 (attribution, PR #95): #103 → #106 → #104 → #105. Builds on the hook #106 lands, so it follows container attribution.
Goal
Let a policy set enforce/audit mode and the default action per workflow step, instead of once for the whole job.
Motivating case: run
enforceacross a job butauditfor one noisy step (a vendored test suite, a flaky integration step) without downgrading the entire job — today--audit-modeis a single boolean fixed for the daemon's lifetime.Why it's small
Phase 0 already ships the hard part. Mode and default action are single-byte values in eBPF array maps, written through idempotent setters (
SetAuditMode,SetDefaultAction) that are already called at runtime when SaaS policy overrides the CLI flag. The work is making the lookup per-policy rather than global:map_audit_mode/map_default_actionlookups incheck_audit_or_block()with a per-policy lookup keyed on the socket's step tag (map_policy_meta[policy_id] → {default_action, audit}).mode/default_actionoverrides on top of the job baseline.Requirements
Done when
A workflow can declare a different mode for one step, the audit log/summary show that step's events under the declared mode, and every other step is unaffected.